There have been a few questions on this before, with some conflicting views on deploying the Splunk Add-On for AWS in a clustered/distributed environment,
The Splunk App for AWS is installed on the Search Heads. No doubts here.
The Splunk Add-On for AWS: If this is being installed and configured on a Heavy Forwarder, is there a need for the Add-On to be installed(but not configured) on the Search Heads? Some posts state that it's only required in one place ie Heavy Forwarder, while others points to it being required on the Search Head as well (for search time logic, field extractions etc), in addition to it being configured on the Heavy Forwarder . (https://answers.splunk.com/answers/213687/where-in-our-splunk-environment-do-we-install-the.html). Can someone who has this deployed and working confirm?